Back to Search Start Over

Watermarking in Secure Federated Learning: A Verification Framework Based on Client-Side Backdooring.

Authors :
WEN YUAN YANG
SHUO SHAO
YUE YANG
XIYAO LIU
XIMENG LIU
ZHIHUA XIA
SCHAEFER, GERALD
HUI FANG
Source :
ACM Transactions on Intelligent Systems & Technology. Feb2024, Vol. 15 Issue 1, p1-25. 25p.
Publication Year :
2024

Abstract

Federated learning (FL) allows multiple participants to collaboratively build deep learning (DL) models without directly sharing data. Consequently, the issue of copyright protection in FL becomes important since unreliable participants may gain access to the jointly trained model. Application of homomorphic encryption (HE) in a secure FL framework prevents the central server from accessing plaintext models. Thus, it is no longer feasible to embed the watermark at the central server using existing watermarking schemes. In this article, we propose a novel client-side FL watermarking scheme to tackle the copyright protection issue in secure FL with HE. To the best of our knowledge, it is the first scheme to embed the watermark to models under a secure FL environment. We design a black-box watermarking scheme based on client-side backdooring to embed a pre-designed trigger set into an FL model by a gradient-enhanced embedding method. Additionally, we propose a trigger set construction mechanism to ensure that the watermark cannot be forged. Experimental results demonstrate that our proposed scheme delivers outstanding protection performance and robustness against various watermark removal attacks and ambiguity attack. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
21576904
Volume :
15
Issue :
1
Database :
Academic Search Index
Journal :
ACM Transactions on Intelligent Systems & Technology
Publication Type :
Academic Journal
Accession number :
174955420
Full Text :
https://doi.org/10.1145/3630636